Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 01 May 2001 10:29:15 -0700
From:      Lars Eggert <larse@ISI.EDU>
To:        Gunther Schadow <gunther@aurora.regenstrief.org>
Cc:        snap-users@kame.net, freebsd-net@freebsd.org, ipfilter@coombs.anu.edu.au, altq@csl.sony.co.jp
Subject:   Re: The future of ALTQ, IPsec & IPFILTER playing together ...
Message-ID:  <3AEEF26B.C6850070@isi.edu>
References:  <3AEEEE79.8F7CC7B0@aurora.regenstrief.org>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Gunther Schadow wrote:
> However, I understand that ALTQ works in the data link layer at
> the interface to the NIC. IPsec, however, works above that layer,
> even before the IPFILTER rules (on outgoing packets.) So, we have
> the following "pipe"
> 
>    IPSEC -----> IPFILTER -------> ALTQ

You should really look into using IPIP tunnels together with IPsec
transport mode. In that case, your packets loop through IP outbound
processing twice, allowing you to hook into "IP hacks" (ALTQ, ipfw,
ipfilter, etc.) at both the virtual network layer as well as the
physical network layer. If (and I'm not sure this is supported, but it's
easy to add) gif devices are ALTQified, you could apply ALTQ at the
virtual network level, before IPsec processing kicks in at the physical
network.

(For our X-Bone overlays, we do Dummynet processing for the virtual
network to simulate delays losses in the VPN; and apply IPsec after
tunneling).

Lars
-- 
Lars Eggert <larse@isi.edu>               Information Sciences Institute
http://www.isi.edu/larse/              University of Southern California
[-- Attachment #2 --]
0#	*H
010	+0	*H
00A#0
	*H
010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.160
000824203008Z
010824203008Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0\p9޻ H;v֐r∩6"C?mxfJf7I[3CF́L	I
-zHRVA怤2]0-bL)%X>nӅw0u0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00U#0`fUXFa#Ì0
	*H
_3	F=%nWY-HXD9UOc6ܰwf@uܶNԄR?Pr}E1֮23mFhySwM_h|d yR=$P 00}0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
990916140140Z
010915140140Z010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.1600
	*H
0iZz]!#rLK~r$BRW{azr98e^eyvL>hput,O	1ArƦ]D.Mօ>lx~@эWs0FO7050U00U#0rIs4Uvr~wƲ0
	*H
kY1rr`HU{gapm¥7؝(V\uoƑlfq|ko!6-	-mƃRt\~
orzg,ksnΝc)	~U100010	UZA10UWestern Cape10UDurbanville10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 1999.9.16#0	+0	*H
	1	*H
0	*H
	1
010501172915Z0#	*H
	1q{(I"_HC'0R	*H
	1E0C0
*H
0*H
0+0
*H
@0
*H
(0
	*H
dM\ v(2#C\5*׉.v̇|#{#$V󻀖IE,[ڔ΍s0R͜>n^og|%0TܧFesS;j

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AEEF26B.C6850070>